Skip to main content
Data Subject Access Requests in Thailand

Data Subject Access Requests in Thailand: New 2026 PDPA Rules

Handling data subject access requests in Thailand is about to become far more prescriptive. In July 2026, the Personal Data Protection Committee (PDPC) finalized a notification that spells out exactly how companies must receive, verify, and answer these requests under the Personal Data Protection Act B.E. 2562 (2019). For years, the right of access existed on paper but lacked a clear procedure. Now the guesswork is gone. Any organization that holds personal data in Thailand, whether a Bangkok subsidiary of a multinational or a foreign-owned e-commerce operator, must align its workflows with fixed channels, verification steps, and response deadlines, or face regulatory exposure.

What Are Data Subject Access Requests in Thailand?

A data subject access request is the formal exercise of an individual’s right to see the personal data an organization holds about them. Section 30 of the PDPA grants every data subject the right to request access to, and a copy of, their personal data, together with information about how that data was obtained without their consent. In practice, employees, customers, job applicants, and former business contacts can all invoke this right against a Thai data controller.

Until recently, the statute set out the right but left the mechanics unclear. Controllers were unsure how to verify identity, how long they had to respond, and when they could lawfully refuse. The new PDPC notification closes that gap. Consequently, businesses can no longer treat these requests as informal correspondence. Instead, they must follow a structured, auditable process from the moment a request arrives.

Key Takeaway: The right of access under Section 30 of the PDPA is not new, but the 2026 PDPC notification is the first instrument to define the procedure. Every controller in Thailand now needs a documented intake, verification, and response workflow.

The New PDPC Notification: What Changed in 2026

The PDPC ran a public consultation on the draft rules from 16 April to 15 May 2026, then finalized the notification and published it in the Government Gazette. The rules take effect 30 days after publication, giving organizations a short runway to adapt. The notification does not create a new right. Rather, it operationalizes the existing one by standardizing procedural requirements that were previously left to each controller’s discretion.

For foreign investors, this shift matters because it raises the compliance bar across the board. A refusal or a missed deadline is no longer a grey area. It is now measurable against a published standard, which makes non-compliance easier for regulators and complainants to establish. Businesses that have already pursued the Thailand PDPA certification framework will find these access rules a natural extension of the same governance discipline. The notification also aligns Thai practice more closely with the GDPR model that many multinational parent companies already follow, so global privacy programs will need local calibration rather than wholesale reinvention.

Scope: What Data a Requester Can Demand

The notification sets a clear floor for what controllers must disclose. When responding to data subject access requests in Thailand, a controller must, at minimum, provide the following.

  • Personal data collected directly from the data subject.
  • Personal data obtained from other sources.
  • The source of any personal data obtained from other sources without the data subject’s consent.

In addition, controllers must make available the transparency information required under Section 23 of the PDPA and the processing details recorded under Section 39, such as the categories of personal data collected and the purposes of processing. Therefore, a well-maintained record of processing activities is not just a standalone obligation. It is the backbone of a compliant access response.

Key Takeaway: A request can reach beyond the data itself to its sources and processing purposes. Controllers that keep an accurate Section 39 record will answer requests faster and with far less legal risk.

How Requests Must Be Submitted and Verified

The notification requires controllers to offer at least two intake channels: in person and by post. Electronic and other channels remain optional, although most modern businesses will want to add them for practicality. A request may come directly from the data subject or through an authorized representative. Either way, it must be signed and must include enough identifying information, a preferred response method, and the details of what the requester wants.

Identity verification sits at the heart of the process. A controller must obtain identity documents and, where a representative acts, proof of authority. Notably, the notification permits different verification methods for requests submitted electronically, provided those methods do not create undue obstacles to the exercise of the individual’s rights. This flexibility helps digital businesses, but it also demands careful design so that verification protects the data without becoming a barrier that a regulator could view as obstructive. Where requests arrive through digital platforms, the interplay with Thailand’s electronic transactions law shapes how a signed, verifiable request can be captured online.

Response Timelines Every Business Must Meet

The most consequential change concerns deadlines. The notification fixes clear timelines that replace the previous uncertainty, and every controller should map these into its internal service levels immediately.

StageDeadlineWhat It Means
Preliminary verificationWithin 7 business days of receiptThe controller must check that the request is complete and the requester’s identity is verifiable.
Cure period for defectsNo less than 10 daysIf a request is incomplete or identity is unverified, the controller sets a deadline (minimum 10 days) to fix it. Missing it means the request is deemed abandoned.
Main responseWithin 30 days of receiptThe clock starts when correct and complete information is provided. The controller must deliver the response within this window.
ExtensionUp to a further 30 daysAvailable for large-volume requests or other necessity, but only if the controller notifies the requester.

Because the response clock resets to the date on which complete and correct information arrives, precise intake logging is essential. A controller that cannot prove when a request became complete will struggle to defend its timeline if a complaint reaches the PDPC.

Key Takeaway: Build the 7-day, 10-day, and 30-day milestones into a tracked workflow. Diarize every deadline, and always notify the requester in writing before relying on the 30-day extension.

When You Can Refuse a Request

The right of access is broad, but it is not absolute. A controller may refuse a request where compliance is prohibited by law or a court order, or where disclosure would adversely affect the rights of third parties. Those third-party interests expressly include fundamental rights, trade secrets, and intellectual property. However, refusal cannot be the default response. Where only part of the data is protected, the controller should apply redaction or other measures and disclose the remainder.

Crucially, any refusal must be communicated with reasons and recorded in the record of processing activities. A silent or unexplained refusal is itself a breach. For businesses that handle competitively sensitive information, this means legal review of borderline requests should happen before, not after, a refusal is issued.

Fees, Recordkeeping, and Practical Compliance

The notification also addresses cost and documentation. Electronic access or copies that require no recording media and involve no direct transmission cost must be provided free of charge. Controllers may charge reasonable, capped fees for physical copies or labor-intensive requests, but only at actual cost and within the schedule set out in the notification. In every case, the controller must tell the data subject about any fees before or at the time the right is exercised.

On recordkeeping, controllers must retain each access request and its supporting evidence for at least two years. This retention rule turns the DSAR process into an audit trail. Regulators can later test whether a business met its deadlines, applied refusals correctly, and charged fees lawfully. As a result, disciplined documentation is now a core compliance safeguard rather than an administrative afterthought. Regulated sectors should also read this notification alongside adjacent duties, such as the insurance cybersecurity rules that impose parallel data governance obligations.

What Foreign Businesses in Thailand Should Do Now

Foreign-owned companies often run global privacy programs that assume a GDPR-style access process. Thailand’s rules are broadly compatible, but they carry local specifics that a generic policy will miss. To prepare for data subject access requests in Thailand, businesses should take the following steps.

  • Publish compliant intake channels. Confirm that in-person and postal channels exist, and design any electronic channel with proportionate identity verification.
  • Map the deadlines into a tracker. Automate the 7-day, 10-day, and 30-day milestones, with alerts and a documented extension-notice template.
  • Refresh your record of processing activities. A current Section 39 record makes responses faster and supports lawful, well-reasoned refusals.
  • Train frontline and HR teams. Staff must recognize a request on arrival, because the clock starts whether or not anyone flags it internally.
  • Pre-clear sensitive scenarios. Agree in advance how you will handle requests that touch trade secrets, third-party data, or ongoing disputes.

Above all, treat the new rules on data subject access requests in Thailand as a live compliance deadline, not a policy footnote. Organizations that act before the effective date will avoid the scramble that inevitably follows the first well-documented complaint to the PDPC.

Frequently Asked Questions

Who can make a data subject access request in Thailand?
Any individual whose personal data a controller holds can make a request under Section 30 of the PDPA. This includes employees, customers, job applicants, and former contacts. A request may be submitted directly by the individual or through an authorized representative who provides proof of authority.
How long does a business have to respond to a request?
The controller must complete preliminary verification within seven business days and deliver the main response within 30 days of receiving a complete, verified request. It may extend this by up to a further 30 days for large-volume requests or other necessity, but only after notifying the requester.
Can a company charge a fee for an access request?
Electronic access or copies that need no recording media and involve no transmission cost must be free. A controller may charge reasonable, capped fees for physical copies or labor-intensive requests, based on actual cost and within the notification’s schedule. The requester must be told of any fee in advance.
When can a controller lawfully refuse a request?
A controller may refuse where the law or a court order prohibits disclosure, or where disclosure would harm third-party rights such as fundamental rights, trade secrets, or intellectual property. Where possible, the controller should redact and provide the rest. Every refusal must state reasons and be recorded in the processing register.
Do these rules apply to foreign-owned companies operating in Thailand?
Yes. The PDPA applies to controllers and processors handling personal data in Thailand, regardless of ownership. Foreign-owned businesses should localize their global privacy procedures to match Thailand’s specific channels, timelines, and recordkeeping requirements rather than relying on a generic international policy.

Businesses handling customer data for campaigns should also review the rules on direct marketing in Thailand under the PDPA.

Need Help Building a PDPA-Compliant Access Process?

Lex Bangkok advises international companies, expatriates, and foreign investors on Thailand’s data protection framework, from DSAR workflows and records of processing to refusals and regulator engagement. Our lawyers translate the new PDPC rules into a practical, defensible compliance program tailored to your business.

Schedule a Consultation